High severity8.0GHSA Advisory· Published May 14, 2024· Updated Apr 28, 2026
CVE-2024-29800
CVE-2024-29800
Description
Deserialization of Untrusted Data vulnerability in Timber Team & Contributors Timber.This issue affects Timber: from n/a through 1.23.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
timber/timberPackagist | >= 2.0.0, < 2.1.0 | 2.1.0 |
timber/timberPackagist | >= 1.24.0, < 1.24.1 | 1.24.1 |
timber/timberPackagist | >= 0.16.6, < 1.23.1 | 1.23.1 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-6363-v5m4-fvq3ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/timber/timber/CVE-2024-29800.yamlghsaWEB
- github.com/timber/timber/commit/13c6b0f60346304f2eed4da1e0bb51566518de4aghsaWEB
- github.com/timber/timber/issues/2971ghsaWEB
- github.com/timber/timber/security/advisories/GHSA-6363-v5m4-fvq3ghsaWEB
- patchstack.com/database/vulnerability/timber-library/wordpress-timber-plugin-1-23-0-deserialization-of-untrusted-data-vulnerabilitynvd
News mentions
0No linked articles in our index yet.